16 Aug
|
Cyberpwn
|
Bengaluru
16 Aug
Cyberpwn
Bengaluru
ROLE OVERVIEW
Serve as the senior technical authority within the Infrastructure Vulnerability Management tower, owning scan strategy, CTEM integration, complex remediation coordination, and prioritisation logic. This role bridges hands-on platform engineering and tower-level delivery, and deputises for the Tower Lead in operational forums.
KEY RESPONSIBILITY AREAS (KRA)
- Own scan strategy and scan policy design across Qualys VMDR and Microsoft Defender for Endpoint TVM, covering cadence, credentialed scanning depth, authentication profiles, and coverage validation.
- Develop and maintain the risk-based prioritisation logic that combines CVSS, exploitability (EPSS and KEV), active threat context, and asset criticality tiers.
- Lead complex and cross-functional remediation coordination with server, network, endpoint, and platform owners, including escalation of at-risk items ahead of SLA breach.
- Execute event-driven and out-of-band scanning in response to zero-day disclosures, threat intelligence triggers, attack surface changes, and Breach and Attack Simulation outcomes.
- Support the zero-day response model through rapid relevance assessment against the estate, confirmation of client-specific exposure, and identification of mitigation pathways.
- Own integration of vulnerability data into CTEM prioritisation workflows, including correlation with consumed asset visibility feeds covering OT, IoT and unmanaged assets, and external attack surface data.
- Drive false-positive reduction, scan tuning, and detection quality improvement across the scanning estate.
- Own the technical content of exception submissions, covering risk articulation, compensating control validation, and evidence supporting approval and renewal decisions.
- Build and maintain reporting and data reconciliation automation to support operational efficiency and accuracy.
- Lead structured backlog reduction workstreams against inherited High and Medium severity findings.
- Mentor Analyst-level engineers and quality-review triage, ticketing, and reporting output.
- Deputise for the Tower Lead in daily stand-ups, weekly operations reviews, and technical working groups as required.
KEY PERFORMANCE INDICATORS (KPIs)
- Accuracy and defensibility of risk prioritisation, measured by the proportion of prioritised findings validated as genuinely exploitable.
- Exposure discovery latency for intelligence-driven and event-driven triggers.
- Scan coverage rate and scan health across in-scope asset classes.
- Reduction in false-positive rate quarter-on-quarter.
- Turnaround time for triage and enrichment of newly identified Critical and High severity vulnerabilities.
- Contribution to inherited backlog burn-down against the agreed plan.
- Quality and completeness of exception submissions at first approval review.
- Timeliness of remediation escalations ahead of SLA breach.
- Automation delivered, measured in analyst hours saved and cycle time reduction.
REQUIRED TECHNICAL SKILLS & EXPERIENCE
- Strong hands-on experience with Qualys VMDR covering scan configuration, authentication records, asset groups,
tagging, reporting, and API usage, with working experience of Microsoft Defender for Endpoint TVM.
- Solid command of CVSS v3.x, EPSS, KEV, and threat-intelligence-informed vulnerability prioritisation.
- Deep OS-level patch management knowledge across Windows and Linux, plus network device and perimeter system vulnerability handling.
- Experience integrating vulnerability data into exposure management or CTEM workflows and dashboards.
- Scripting and automation (PowerShell, Python) for scanner API integration, reporting pipelines, and data reconciliation.
- Working knowledge of CMDB concepts, asset criticality classification, and reconciliation of discovered assets against authoritative inventory.
- Experience with ServiceNow and Azure Boards for remediation ticket lifecycle management, with Power BI reporting exposure an advantage.
- Comfortable operating in a multi-vendor environment and collaborating constructively with a separate defensive security partner.
WORKING WORKPLACE & CONDUCT
- Onsite presence at the client delivery centre in Bangalore five days per week is a mandatory condition of the role.
- Candidates must meet client-defined competency, certification, background verification, and conduct standards prior to onboarding.
PREFERRED / EXPECTED CERTIFICATIONS
- Qualys VMDR certification (vendor-relevant, strongly preferred)
- CompTIA Security or equivalent foundational security certification
- CEH or equivalent (preferred, not mandatory)
EDUCATIONAL QUALIFICATION
Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field (or equivalent practical experience).
📌 Infra VM - Sr VM Analyst (Bengaluru)
🏢 Cyberpwn
📍 Bengaluru